Junglewise Threat Intelligence

CVE-2026-57279: Cybozu Garoon cross-site scripting in Scheduler

CVE-2026-57279 · Severity: medium · CVSS 6.8 · Published 2026-08-10

Executive brief

Cybozu Garoon is a web-based enterprise collaboration platform used for scheduling, messaging, and team coordination. A cross-site scripting (XSS) vulnerability in the Scheduler component allows an attacker to execute arbitrary JavaScript in the browser of a logged-in user. This could lead to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim within the platform.

Technical details

The vulnerability is a stored or reflected cross-site scripting flaw (CWE-79) in the Scheduler component of Cybozu Garoon, affecting versions 6.17.0 and 6.17.1. The flaw stems from improper neutralization of user input during web page generation. The attack requires network access, low privileges (user must be logged in), and user interaction (e.g., clicking a malicious link). An attacker can inject and execute arbitrary JavaScript in the victim's browser context, potentially accessing or modifying data within the Garoon session. The vulnerability was patched in version 6.17.2; users are advised to upgrade immediately.

Affected products

  • Cybozu Garoon 6.17.0 to 6.17.1

Timeline

  • 2026-08-03: disclosed
  • 2026-07-31: patched: Patch released in version 6.17.2

References